Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.5 CVE-2025-54376 Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, Hoverfly’s admin WebSocket endpoint /api/v2/ws/logs is not protected by… Hoverfly 1.12.0+ Fix from $1,9502025-09-10 MEDIUM 5.7 CVE-2025-56578 An issue in RTSPtoWeb v.2.4.3 allows a remote attacker to obtain sensitive information and executearbitrary code via the lack of authentication mecha… Mitigation only Fix from $1,6002025-09-10 HIGH 7.1 CVE-2025-10224 Improper Authentication (CWE-287) in the LDAP authentication engine in AxxonSoft Axxon One (C-Werk) 2.0.2 and earlier on Windows allows a remote auth… Axxon One after 2.0.2 Fix from $1,9502025-09-10 HIGH 8.8 CVE-2025-57278 The LB-Link BL-CPE300M AX300 4G LTE Router firmware version BL-R8800_B10_ALK_SL_V01.01.02P42U14_06 does not implement proper session handling. After … Bl Cpe300m Firmware No fix yet Fix from $1,9502025-09-09 CRITICAL 9.8 CVE-2025-55234EPSS 20% SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could p… Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $2,3002025-09-09 HIGH 8.8 CVE-2025-54918EPSS 19% Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network. Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,9502025-09-09 CRITICAL 9.8 CVE-2025-9994 The Amp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not have an authentication feature, allowing unauthorized access to anyone… Mitigation only Fix from $2,3002025-09-09 CRITICAL 9.1 CVE-2025-58443EPSS 19% FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1673 and below contain an authentication bypass v… Fogproject after 1.5.10.1673 Fix from $2,3002025-09-06 CRITICAL 10.0 CVE-2025-55241 Azure Entra ID Elevation of Privilege Vulnerability Entra Id No fix yet Fix from $2,3002025-09-04 HIGH 8.8 CVE-2025-26438 In smp_process_secure_connection_oob_data of smp_act.cc, there is a possible way to bypass SMP authentication due to Incorrect implementation of a pr… Android Patch available Fix from $1,9502025-09-04 CRITICAL 9.4 CVE-2025-56752 A vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote attackers to fully bypass authentication mechanisms, provid… Rg Es228gs P Firmware Mitigation only Fix from $2,3002025-09-03 CRITICAL 9.8 CVE-2023-21467 Error in 3GPP specification implementation in Exynos baseband prior to SMR Apr-2023 Release 1 allows incorrect handling of unencrypted message. Exynos Mitigation only Fix from $2,3002025-09-03 HIGH 7.3 CVE-2024-40653 In multiple functions of ConnectionServiceWrapper.java, there is a possible way to retain a permission forever in the background due to a logic error… Android Mitigation only Fix from $1,9502025-09-02 HIGH 7.8 CVE-2025-9815 A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS. The affected element is an unknown function of the file PrivilegeHelper/Pr… Batterykid after 2.1 Fix from $1,9502025-09-02 CRITICAL 9.8 CVE-2025-52856 An improper authentication vulnerability has been reported to affect VioStor. If a remote attacker, they can then exploit the vulnerability to compro… Qvr 5.1.6+ Fix from $2,3002025-08-29 MEDIUM 5.3 CVE-2025-52054 An issue was discovered in Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router AC8v4.0 Firmware 16.03.33.05. The root password of the device is c… Ac8 Firmware after 16.03.33.05 Fix from $1,6002025-08-28 CRITICAL 9.8 CVE-2025-7955 The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to improper validation within the ringcentral_admin_lo… Mitigation only Fix from $2,3002025-08-28 CRITICAL 9.8 CVE-2025-9533EPSS 9% A vulnerability has been found in TOTOLINK T10 4.1.8cu.5241_B20210927. Affected is an unknown function of the file /formLoginAuth.htm. The manipulati… T10 Firmware Mitigation only Fix from $2,3002025-08-27 CRITICAL 9.8 CVE-2024-52786 An authentication bypass vulnerability in anji-plus AJ-Report up to v1.4.2 allows unauthenticated attackers to execute arbitrary code via a crafted U… Mitigation only Fix from $2,3002025-08-22 CRITICAL 9.8 CVE-2024-50645 MallChat v1.0-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to access API without any token. Mitigation only Fix from $2,3002025-08-22 CRITICAL 9.8 CVE-2024-50644 zhisheng17 blog 3.0.1-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to access API without any token. Mitigation only Fix from $2,3002025-08-22 HIGH 8.1 CVE-2024-50641 An authentication bypass vulnerability in PandoraNext-TokensTool v0.6.8 and before. An attacker can exploit this vulnerability to access API without … Mitigation only Fix from $1,9502025-08-21 CRITICAL 9.8 CVE-2025-52395 An issue in Roadcute API v.1 allows a remote attacker to execute arbitrary code via the application exposing a password reset API endpoint that fails… Mitigation only Fix from $2,3002025-08-21 CRITICAL 9.8 CVE-2025-50901 JeeWMS 771e4f5d0c01ffdeae1671be4cf102b73a3fe644 (2025-05-19) contains incorrect authentication bypass vulnerability, which can lead to arbitrary file… Jeewms Mitigation only Fix from $2,3002025-08-20 CRITICAL 9.8 CVE-2024-50640 jeewx-boot 1.3 has an authentication bypass vulnerability in the preHandle function Mitigation only Fix from $2,3002025-08-20 HIGH 8.8 CVE-2024-57491 Authentication Bypass vulnerability in jobx up to v1.0.1-RELEASE allows an attacker can exploit this vulnerability to access sensitive API without an… Mitigation only Fix from $1,9502025-08-20 CRITICAL 9.8 CVE-2025-55293 Meshtastic is an open source mesh networking solution. Prior to v2.6.3, an attacker can send NodeInfo with a empty publicKey first, then overwrite it… Meshtastic Firmware 2.6.3+ Fix from $2,3002025-08-18 HIGH 7.8 CVE-2025-8964 A vulnerability was identified in code-projects Hostel Management System 1.0. This affects an unknown part of the file hostel_manage.exe of the compo… Hostel Management System No fix yet Fix from $1,9502025-08-14 CRITICAL 9.8 CVE-2025-51451 In TOTOLINK EX1200T firmware 4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm. Ex1200t Firmware Mitigation only Fix from $2,3002025-08-13 HIGH 7.5 CVE-2025-55171 WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, the application does… Wegia 3.4.8+ Fix from $1,9502025-08-12